Cisco VPN :: ASA5505 / C2621XM - Join Two Sites Over Internet
Jul 23, 2012I want to join two sites over an internet connection using a Site-to-Site VPN over an ASA5505 and C2621XM Router. The ASA is on IOS 8.4 and the router is 12.4.
View 2 RepliesI want to join two sites over an internet connection using a Site-to-Site VPN over an ASA5505 and C2621XM Router. The ASA is on IOS 8.4 and the router is 12.4.
View 2 RepliesI currently have a "hub" ASA 5505 that links to 4 sites running 877 routers. From the hub network i can connect to all sites fine but what i would like to do is to almost compartmentalise the various VPN links into little clusters.The hub ASA 5505 basically provides IP telephony through the VPN's from a PBX allowing the users at the other end of the VPN to make outgoing calls and recieve incoming calls. However, a couple of the sites would like to be able to call between eachother internally via the hub. This obviously requires traffic to be allowed between their various networks. Currently when you attempt an internal call it rings but there is no audio either way. I assume this is due to access list restrictions. I am not even sure whether what I am trying to achieve is possible. I've attached the hub and 2 spokes below. The ideal end result would be interconnectivity between the two spokes via the hub, from reading up it would seem that its possible but i can't quite get my head around it! Would it involve using different subnet masks at the hub?
View 1 Replies View RelatedI manage to configure the firewall 5505 so that it can ping between outside and DMZ and also between DMZ and inside.
Outside and Inside are not accessible to each other because Outside No Forward to Inside.
My purpose now wants to access the shared folder by Windows Explorer ( under Network ) between for example DMZ and inside. I tried to do it but cannnot even see the Host of the other party network. For example, if I open Windows explorer at DMZ, I can't see the Host at Inside Network. Same as I open Windows Exploere at Inside, I can't see also the Host at DMZ network.
How am I configure so that I can access the hsot as well as shared folder of two sites which already can ping each other?
MY ISP installed one router in my lab.for internet connectivity they mail me steps :connect your Laptop directly to gi0/3 port to check internet connectivity with public ip 1.1.1.x and Gateway 1.1.1.1 with subnet mask 255.255.255.240 after connection I surprised because I am able to access only google sites like gmail,google search etc. but I am able to ping/traceroute all sites.from browser I am able to access only google sites only.In Router no firewall no such access list.
View 2 Replies View RelatedI can't access my ad sites through my internet. I can access them through my phone internet and others are not having any problems going to them
View 3 Replies View RelatedI am having an issue with my computer that started today. Here are the basic facts:1. Nearly every internet site I try to visit does not load. Facebook and Wikipedia work, as well as ALL Google sites (including YouTube, Gmail, Google News, etc.). Nothing else I have tried to load is loading properly. 2. It could be a coincidence, but these three sites were also my Firefox bookmarks. However, I have reset the default settings for Firefox (including bookmarks) and these three sites still work and nothing else. Additionally, these three sites load in Internet explorer, so the problem isn't specific to Firefox. 3. I don't believe it's a problem with my router/internet connection because I have another computer on the same connection that's working fine (I'm typing this message on the other computer). 4. I successfully pinged other websites using Command.5. I suspect it MIGHT be malware/virus because I have no anti-virus/anti-malware software on the computer that's having problems.
View 1 Replies View RelatedI'm having problems connecting to certain sites on the internet through one computer. I can connect ok on other computers going through the same home network. On the one computer that is having problems I can connect to the site but then when I click on a link I get unable to connect then I can reload the page and some times it connects to the page. So as I am browsing through the site almost every time I click on a link I get unable to connect and have to keep reloading the page.
View 5 Replies View Relatedruns fine till i get on youtube then plays a peice of video then dissconects and reconnects and video will not play
View 1 Replies View RelatedI have today the issue that I am unable to load certain websites, I can enter but whenever I click on continue to navigate in that same site for example FACEBOOK, I see the operation just loads and dont go anywhere, after that remains in same condition unless I cancel or close the browser.I checked the firewall, and also the antivirus, but nothing seems wrong, I can get in into HOTMAIL, GOOGLE, but again certain sites if I search something on GOOGLE, get frozen again .
View 1 Replies View RelatedI am having trouble with my wireless connection. I am only able to visit websites but if I try to use the internet for anything else (AIM, Yahoo instant messenger, etc), it will not work. This is not a modem issue because my other computers' connections still work fine.
Configuration Host Name . . . . . . . . . . . . : JingJunBusiness
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
[code]....
I am currently at university, using a Local Area Connection. I am aware that the university blocks torrenting which I am totally fine with though when I try to carry out a process such as posting a large entry on Livejournal.com or Dreamwidth.org, it tries to load for a couple seconds and then fails. When in Google Chrome, it says that it's "uploaded 100%" but then I receive "Error 7 (net::ERR_TIMED_OUT): The operation timed out.". When using Internet Explorer, it either doesn't load at all or I get the standard "Internet Explorer cannot display the webpage". When I try to carry out a different process on dreamwidth and livejournal (editing my layout), Chrome tells me "Error 101 (net::ERR_CONNECTION_RESET): The connection was reset." These issues always happen no matter when I try them.
View 2 Replies View RelatedMy bsnl wimax connection has stopped working on my laptop...IT WORKS ON MY FREINDS' LAPTOP. On my laptop (windows 7), in the taskbar, it shows connected and everything seems fine but i cant access any sites or download anything? Does this have to do with a bluetooth device i installed a few days back or some other issue.
View 3 Replies View RelatedI have ATT DSL and pretty much every night, I lose a large portion of the Internet. I cannot ping these sites, while the rest of the net works fine. The other night, I could not ping major domains like ATT, CNN, MSNBC, BBC (a chronic missing domain). On the other hand, I could get Yahoo fine and go to a streaming audio site and run music perfectly...but about 90% of the Internet was unreachable. Could not load their sites nor ping them in command line. The other 10% worked flawlessly.
View 12 Replies View RelatedMy Toshiba will not connect. I keep getting cannot connect to server messages. Also get the error 623 message. Im not sure what to do. I use Windows xp on it. Bought it in 2006. I had thought about reseting it to factory settings but I never made restore disks and cannot find the toshiba reset stuff.
View 1 Replies View RelatedI'm using my iPhone to write this, because any other site that's not google just ends up as a blank white screen!Internet connection is 5 bars, and I tried cable and changing DSN servers.
View 4 Replies View RelatedSo i just brought my computer home from my dorm where it was working fine. as it is in my rom now I bought the XAVB1004 from netgear to connect it from my room t the router in the computer room. That device works great as I have tried my laptop with it and it works. I can connect to the internet as i have set u my router on my computer( the one that i took from my dorm) but only google loads, i can also search in google, and youtube loads where i can oddly watch videos no problem. I have tried reinstalling my ethernet drivers, winsock reset, checking/unchecking just about every setting in internet options and so on. No browser seems to work and I am out of ideas. I turned firewall off as well to no prevail. I have no clue where to look next as 3 days ago my computer worked fine and all I did now was move it.
View 7 Replies View RelatedI am having BSNL broadband & netgear router. Some of the sites are not opening like [URL] many more?
View 4 Replies View RelatedI just upgraded my old WRT54G to a E4200v2 with firmware 2.0.36.126507. I installed it using the Cisco Connect CD. At first it seemed OK, but then I noted that I cannot open (or takes forever) many websites, in particular those requiring Adobe Flash Player to view. In addition, it appears that access IPv6 Internet or sites is impossible, even though IPv6 is enabled in the GUI. Is there anything I am missing in the configuration/set up of the router?
View 9 Replies View RelatedI want to block sites like facebook during my workday but allow the rest of the internet.
The attached settings block facebook as desired during the filter times but after 6:30pm the filter expires and the entire internet is blocked (not just facebook). All of my browsers act as if they are hanging and won't load pages until I disable the filter.
I've also tried creating two different filters (one at a time). The first allowed full internet access all the time and the second allowed access the opposite times of the work filter. But to no avail.
how do I block IP/Internet Adresses for ALL users without adding the sites manually per user in the Parental Control panel? I want to block a certain IP/internet adress for all users but can't find this feature within my EA6500 anywhere?Is this a firmware bug? Has linskys forgotten that some sites want to blocked for all users and how do I do it all in one?
View 1 Replies View RelatedI want internet for the clients behind the ASA. When i made an entry like:
object network as-us-db11_internet
nat (inside,outside) dynamic nat_usa_pool_72
access-group inside_access_in in interface inside
access-group outside_access_in in interface outside
then have the computer internet but the Client vpn connection wont work. i can not connect to the computer over vpn. but vpn connection worked.
Recently installed an ASA5505 for a client. They have Verizon DSL (7mb down, 384up package). So my config is Verizon (Westell) DSL modem connected to e0/0 (VLAN2) of ASA. From there I have e0/1 (VLAN1) connected to a 3COM 2250 Plus 50 port switch.
Since installing the ASA client has been complaining of a major slow down in Internet speed. Contacted ISP and they had me remove the firewall from the equation and hook modem directly to laptop. With this setup I get between 6-7mb download speeds. When I put the ASA back into the mix though, the speed drops significantly. The speed will varry but 90% of the time they do not even get 1mb download speeds.
The configuration is pretty straight forward, not doing a whole lot with the box other then using it for VPN (IPSEC).
There is web server at the internet. The firewall ASA5505 is located at the inside edge of the edge router and the internet is at the outside edge router of the edge router. The router has already been configured can route the outside network of firewall to internet. [code]
1. I have a host at the DMZ zone of firewall and if it wants to access this web server by http, the following command lines to be added to ASA5505 good enough and anything wrong with them? [code]
2.I have a doubt here that do I need to add any command line related to the Static Mapped address of 192.168.20.10/24 like below?
access-list Outside_DMZ extend permit tcp any 192.168.20.10 255.255.255.0 eq 80.whereby the 192.168.20.10 is the static mapped address of the Host at the DMZ to Outside Nertwork. Or, any other command related with the Static Mapped address have to be added?
Recently, I have bought an ASA 5505 firewall which I have tried to connect to my ADSL router (Modem).It is now more than a week that I am trying to get internet connection through the firewall but I still can't succeed. I have tried many advices I get from this community but I still don't know what is wrong with my ASA Firewall configuration. From inside I am able to ping the inside and outside interface with a great success. and from my laptop which is connected to the firewall, I am able to ping the both interfaces (inside and outside) but still I can't access the internet.
As I don't have a static IP address from my ISP, I have configured the outside interface to pick up the ip address dynamically. Most of the time, the outside interface get the 192.168.1.2 ip address. [code]
When remote workers - working say from home connect into the company's LAN via an ASA5505, is it then possiable to then go back out to the internet using the ASA as the gateway to the internet.It works if I point towards an internal proxy server.
View 4 Replies View RelatedI have configured ASA 5505 for remote access VPN to allow remote user to connect to the officce LAN from remote locations. VPN working fine, users can access offce LAN and sahred resource etc but once they connected to VPN, they can not browse the internet ? Internet browsing stop working as soon as their VPN client connnect with ASA 5505 t, once they are disconnected from the VPN , again they can browse the internet.
Does ASA 5505 blocks the internet browsing for VPN users ? Is there anything else I need to congfure to make sure VPN users can browse internet? Do I need to configure Split Tunnleing , NATing or routing for the VPN users?
I teach in a High School and we've got about a 300 node MS Windows Network. Two MS2003 File Servers act as my DNS/WINS/DHCP servers. We have been using a WATCHGUARD FIREBOX III to act as the router/gateway between the outside external address and my internal (10.0.0.1) gateway address. All p.c's inside the network are routed to one of the Servers (10.0.0.2 or 10.0.0.4) for DNS/WINS/DHCP addressing. The servers point to 10.0.0.1 for gateway.
We are trying to replace the Watchguard Firebox with a CISCO ASA 5505 (eventually we'd like to implement VPN). When I connect the CISCO ASA, I get no internet passthrough at all.
I've been struggling with gaining access to the inter through our Comcast business gateway. We have had Comcast configure the device fro true static IP subnetting. Turned of local DHCP on the device etc. Here is my config.
ASA Version 9.1(1)
!
hostname TOCN-EX-01A-C5505-GW
xlate per-session deny tcp any4 any4
xlate per-session deny tcp any4 any6
xlate per-session deny tcp any6 any4
[code]....
I would hereby like to inform if it is possible to configure the Cisco ASA5505 firewall to route internet via an external VPN, while a laptop and smartphone connect to the firewall via Cisco AnyConnect VPN.
The configuration would result into: Laptop on public internet -> Cisco ASA5505 VPN -> External VPN (Unix server) -> internet.
I have a ASA5505 and I'm having trouble to achieve the following setup, block any kind of connection from outside except for IIS on port 80 and 443 but allow from the server to access any outside address, by domain or ip. Right now apps writen in C# on the server are throughing socket errors and Teamviewer remote control is not working, I would like it to replace remote desktop.
View 3 Replies View RelatedHow can I get DMZ hosts to be able to access the Internet via the Outside interface of my ASA5505.I am using the DMZ to allow temp guest acces to the Internet.
Here is my configuration and it can be changed as needed.
User Access Verification
Password:Type '?' for a list of available commands.ciscoasa> enaPassword: *******ciscoasa# sho run: Saved:ASA Version 8.0(4)!
interface Vlan1nameif insidesecurity-level 100ip address 192.168.100.39 255.255.255.0!interface Vlan8no forward interface Vlan1nameif dmzsecurity-level 50ip address 172.31.10.1 255.255.255.0!interface Vlan11nameif outsidesecurity-level 0ip address 24.172.82.xxx 255.255.255.252!interface Ethernet0/0!interface Ethernet0/1switchport access vlan 11!interface Ethernet0/2!interface Ethernet0/3switchport access vlan 8!interface Ethernet0/4!interface Ethernet0/5!interface Ethernet0/6!interface Ethernet0/7!boot system disk0:/asa804-k8.binftp mode passivedns server-group DefaultDNSdomain-name asaobject-group protocol DM_INLINE_PROTOCOL_1protocol-object udpprotocol-object
[code]...
I have a 100MB pipe coming.I have one ASA5505. This is the current backbone to the whole system.I want to send internet to 16 different locations via microwave dishes.So, many problem is my pipe is 100 Mbps , want to cut that large pipes into a bunch of small pipes. Per pipe 2 Mbps.So, I can send this B.W ( 100 Mbps ) to 50 Users.
I have only ASA 5505 and L2 switch for Vlan purpose. I heard by using RADIUS server we can do this but I don't know how to do. IF yes, then some Docs regarding that one.
I am able to successfully connect to my ASA5505 via AnyConnect via a mobile device. Upon doing so, I lose internet connectivity. My access list appear to be correct to I'm sort of at a loss.
[code]....